Skip to main content

CVE-2024-20953

8.8
HIGHCVSS v3.1 Base Score
67.91%
MEDIUM RiskEPSS (99th percentile)
KEV
NVD-CWE-noinfo

Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Export). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in takeover of Oracle Agile PLM. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

Published: 2/17/2024
Modified: 10/27/2025
Back to CVE Lookup

ACTIVELY EXPLOITED IN THE WILD

This vulnerability is listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Vulnerability Name:

Oracle Agile Product Lifecycle Management (PLM) Deserialization Vulnerability

Vendor / Product:

Oracle Agile Product Lifecycle Management (PLM)

Required Action:

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Due Date: 3/17/2025(OVERDUE)
Added to KEV:

2/24/2025

Notes:

https://www.oracle.com/security-alerts/cpujan2024.html ; https://nvd.nist.gov/vuln/detail/CVE-2024-20953

Vulnerability Summary

CVSS v3 Score

8.8HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS Score (Exploitation Probability)

67.91%MEDIUM Exploitation Risk
99th percentile

This vulnerability has a 67.91% probability of being exploited in the next 30 days, ranking higher than 99% of all scored CVEs.

CWE Classification

NVD-CWE-noinfo

Related Vulnerabilities